← All Advisories

CVE-2026-97536

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97536

Key Details

CVECVE-2026-97536
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is adjacent; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown

The response queue MSI-X handler qla2xxx_msix_rsp_q() schedules

qla_do_work() via queue_work(ha->wq, &qpair->q_work). qla_do_work()

dereferences the qpair (vha, rsp) and takes qpair->qp_lock.

During teardown, qla2xxx_delete_qpair() deletes the response queue, which

calls free_irq() in qla25xx_free_rsp_que(), and then frees the queue and

the qpair. free_irq() waits for running hardirq handlers but does not

cancel work already placed on ha->wq. A still-pending q_work then runs

qla_do_work() against the freed qpair and response queue, causing a

use-after-free. This is especially likely during full adapter teardown,

where destroy_workqueue(ha->wq) forces pending work to run after the queue

pairs have been freed.

Flush the work item with cancel_work_sync() in qla25xx_free_rsp_que()

after free_irq() has released the interrupt (so no new work can be

queued) and before the response queue and qpair memory are freed (so the

flushed handler still sees valid memory). Guard on rsp->qpair and ha->wq

to match the INIT_WORK() condition and avoid operating on an

uninitialized work_struct. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97536
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97536